Abstract: A cybersecurity system for an information and technology system is presented. The cybersecurity system includes: a risk engine that detects past events in the information and technology system, the risk engine including an electronically stored set of rules characterizing events; a prevention engine that models events in the information and technology system, the prevention engine including a model builder, the prevention engine communicatively coupled to the risk engine; and a user interface communicatively coupled to the risk engine and to the prevention engine; where the model builder is configured to build at least one attack tree based on a past event detected by the risk engine and a potential event modeled by the prevention engine, and where the cybersecurity system is configured to report the at least one attack tree through the user interface, such that a future event depicted in the at least one attack tree can be remediated.
Type:
Grant
Filed:
March 25, 2022
Date of Patent:
October 22, 2024
Assignee:
SAIX INC.
Inventors:
Hemanth Shenoy, Vardaan Sharma, Phanindra Banda
Abstract: A system for managing cyber security risks includes a memory storing instructions and a processor that executes the instructions to perform operations. The operations include receiving raw entity data for one or more entities from a source system and converting the raw entity data to processed entity data having a format different from the first entity data. The operations include extracting attributes for the entities from the processed entity data and generating an initial risk score for a selected entity based on an entity initial attribute associated with that entity. The operations also include receiving a rule for determining a rule-based risk score and generating a rule-based risk score for the selected entity based on the entity attribute of the selected entity. Additionally, the operations include generating a risk score for the selected entity based on the initial and rule-based risk scores.
Abstract: A system for managing cyber security risks includes a memory storing instructions and a processor that executes the instructions to perform operations. The operations include receiving raw entity data for one or more entities from a source system and converting the raw entity data to processed entity data having a format different from the first entity data. The operations include extracting attributes for the entities from the processed entity data and generating an initial risk score for a selected entity based on an entity initial attribute associated with that entity. The operations also include receiving a rule for determining a rule-based risk score and generating a rule-based risk score for the selected entity based on the entity attribute of the selected entity. Additionally, the operations include generating a risk score for the selected entity based on the initial and rule-based risk scores.